Session Fixation in snipe/snipe-it
Valid
Reported on
Aug 22nd 2022
Description
The session is not invalidated after a password change.
Proof of Concept
Open Snipe-IT in the browser and login. Do the same in a private window such that there are two sessions. Change the password in one of the two sessions and observe that the second session is not invalidated.
Impact
An old session can be used even after the password has been changed.
We are processing your report and will contact the
snipe/snipe-it
team within 24 hours.
a year ago
We have contacted a member of the
snipe/snipe-it
team and are waiting to hear back
a year ago
The researcher's credibility has increased: +7
to join this conversation